CVE-2026-68148: fscrypt: Add missing superblock check in find_or_insert_direct_key()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081001-CVE-2026-68148-7d8c@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy 'fscrypt_direct_keys' table caches master keys that are used by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY. It's just a global table for all filesystems (since the keys can be provided by the legacy process-subscribed keyrings mechanism, which makes it difficult to reuse super_block::s_master_keys). The entries in it ('struct fscrypt_direct_key') do contain a super_block pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when the last inode that references the key is evicted. However, when finding the fscrypt_direct_key for an inode, we weren't actually comparing the super_block pointer. As a result, inodes with different super_blocks could point to the same fscrypt_direct_key. That could extend the lifetime of a fscrypt_direct_key beyond the super_block it points to, causing a use-after-free later. Fix this by creating distinct fscrypt_direct_key structs for distinct super_block structs. Note that this problem doesn't exist in the v2 policy equivalent ("per-mode keys"), since the data structures there are per super_block. The Linux kernel CVE team has assigned CVE-2026-68148 to this issue. Affected and fixed versions =========================== Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.6.148 with commit 330249609b70778094a7a36f5b6bcfa6362121d4 Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.12.101 with commit deff41898a5ae3a47db5fa1896a494aa95efda5d Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.18.42 with commit 95376fe9c145be35566991df99c53134943d992f Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 7.1.6 with commit 466f187b501a5ac8e1ea2ccf3ccd5c46108d8830 Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 7.2-rc5 with commit b5fa40226e71c17847b9ff2816c6ca4133d0d994 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-68148 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/crypto/keysetup_v1.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4 https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830 https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994